Ubuntu下Tomcat安全设置清单
一 基础加固
二 身份与访问控制
<tomcat-users>
<role rolename="manager-gui"/>
<role rolename="admin-gui"/>
<user username="admin" password="StrongPass!2025" roles="manager-gui,admin-gui"/>
</tomcat-users>
三 网络与端口
四 运行与部署配置
[Service]
User=tomcat
Group=tomcat
UMask=0007
Environment=JAVA_HOME=/usr/lib/jvm/java-11-openjdk-amd64
Environment=CATALINA_HOME=/opt/tomcat
Environment=CATALINA_BASE=/opt/tomcat
ExecStart=/opt/tomcat/bin/startup.sh
ExecStop=/opt/tomcat/bin/shutdown.sh
Restart=always
然后执行:sudo systemctl daemon-reload && sudo systemctl enable --now tomcat。sudo chown -R tomcat:tomcat /opt/tomcat
sudo chmod -R g+r /opt/tomcat
sudo chmod -R g+w /opt/tomcat/logs /opt/tomcat/temp /opt/tomcat/work /opt/tomcat/webapps
五 监控与维护